Vulnerabilities
Vulnerable Software
Vignette:  Security Vulnerabilities
Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.
CVSS Score
4.3
EPSS Score
0.004
Published
2003-06-30
Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.
CVSS Score
5.0
EPSS Score
0.009
Published
2003-06-30


Contact Us

Shodan ® - All rights reserved